Skip to content

Security: kucherenko/jscpd

SECURITY.md

Security Policy

Supported Versions

Version Branch Supported
5.x (Rust engine) master ✅ Active development
4.x (TypeScript engine) master-v4 ✅ Security fixes only
< 4.0 — ❌

Reporting a Vulnerability

Please report security vulnerabilities privately — do not open a public issue.

Please include a description of the issue, steps to reproduce, affected versions, and any known impact.

You can expect an acknowledgement within 7 days. Once a fix is available, it is released for the supported version lines and the advisory is published with credit to the reporter (unless you prefer to stay anonymous).

Fixed vulnerabilities are identified in the release notes and changelog of the release that contains the fix, with a reference to the published advisory: rust/CHANGELOG.md for 5.x, and CHANGELOG.md on the master-v4 branch for 4.x.

There aren't any published security advisories